WeChat Official AccountSAFE
微信公众号MCP服务器 - WeChat Official Account MCP Server
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
一个为 AI 应用提供微信公众号 API 集成的 MCP (Model Context Protocol) 服务项目。
作者: xwang152-jack 更新日期: 2026年05月24日
🚀 项目概述
本项目基于 MCP 协议,为 AI 应用(如 Claude Desktop、Cursor、Trae AI 等)提供完整的微信公众号 API 集成。通过标准化的工具接口,AI 应用可以轻松管理微信公众号的用户、标签、菜单、素材、草稿、发布、消息、数据统计、二维码、评论、黑名单等所有核心功能。
当前版本: v2.2.0 (查看 CHANGELOG | v1.1.0 Release Notes)
v2.2.0 更新: 新增 6 个工具模块(二维码、短链接、评论管理、黑名单、客服账号、账号管理),从 15 个工具扩展到 21 个工具。
📖 文档导航
- 功能总览 (FEATURES_OVERVIEW.md) - v2.0.0 完整功能介绍、对比表格和使用场景
- 更新日志 (CHANGELOG.md) - 版本历史和详细更新内容
- 开发者指南 (CLAUDE.md) - 架构说明、开发规范、常见模式
外部资源
✨ 核心功能
- 🔐 认证管理: 安全管理微信公众号 AppID、AppSecret 和 Access Token
- 📁 素材管理: 上传、获取、管理临时和永久素材
- 📝 草稿管理: 创建、编辑、管理图文草稿
- 📢 发布管理: 发布草稿到微信公众号
- 💾 本地存储: 使用 SQLite 本地存储配置和数据
- 🔧 MCP 集成: 完全兼容 MCP 协议标准
- 🛡️ 安全增强(v1.1.0): 支持敏感字段加密存储与日志脱敏,跨域来源白名单配置
🛠️ 技术栈
- 运行时: Node.js 18+
- 语言: TypeScript
- 协议: MCP (Model Context Protocol)
- 数据库: SQLite
- HTTP 客户端: Axios
- 参数验证: Zod
- 构建工具: Vite
📦 快速开始
方式一:使用 npx(推荐)
直接使用 npx 运行,无需安装:
# 启动 MCP 服务器 npx wechat-official-account-mcp mcp -a -s # 示例 npx wechat-official-account-mcp mcp -a wx1234567890abcdef -s your_app_secret_here
提示:如使用 SSE 模式,请设置 CORS_ORIGIN 为允许访问的域名白名单。方式二:全局安装
# 全局安装 npm install -g wechat-official-account-mcp # 启动服务 wechat-mcp mcp -a -s
方式三:本地开发
# 1. 克隆项目 git clone https://github.com/xwang152-jack/wechat-official-account-mcp.git cd wechat-official-account-mcp # 2. 安装依赖 npm install # 3. 构建项目 npm run build # 4. 启动服务 node dist/src/cli.js mcp -a -s
CLI 参数说明
-a, --app-id: 微信公众号 AppID(必需)- `-s, --app-s
ef650a6aba94OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add wechat-official-account-mcp --env WECHAT_MCP_SECRET_KEY=${WECHAT_MCP_SECRET_KEY} -- npx -y [email protected]{
"mcpServers": {
"wechat-official-account-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"WECHAT_MCP_SECRET_KEY": "${WECHAT_MCP_SECRET_KEY}"
}
}
}
}Exposed tools (21)
17 read · 4 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
wechat_account | read | 微信公众号账号管理工具。查询API调用次数配额、重置API调用次数。用于监控和管理公众号接口调用频率。 |
wechat_auth | read | 管理微信公众号认证配置和 Access Token |
wechat_auto_reply | read | 微信公众号自动回复规则 - 查询当前的自动回复规则配置 |
wechat_blacklist | read | 微信公众号黑名单管理工具。查看黑名单列表、拉黑/取消拉黑用户。被拉黑的用户无法收到公众号消息。 |
wechat_comment | read | 微信公众号评论管理工具。管理已群发文章的评论,包括打开/关闭评论、查看评论列表、精选/删除/回复评论。 |
wechat_customer_service | read | 微信公众号客服消息 - 发送客服消息(文本、图片、语音、视频等),获取聊天记录 |
wechat_draft | read | 管理微信公众号草稿 |
wechat_kf_account | read | 微信公众号客服账号管理工具。添加、修改、删除客服账号,获取客服列表。客服账号用于管理多客服人员。 |
wechat_mass_send | write | 微信公众号群发消息 - 根据标签或OpenID列表群发图文、文本、图片等消息,支持删除和预览 |
wechat_media_upload | write | 上传和管理微信公众号临时素材(图片、语音、视频、缩略图) |
wechat_menu | read | 微信公众号自定义菜单管理 - 创建、查询、删除菜单,支持个性化菜单 |
wechat_permanent_media | read | 管理微信公众号永久素材,支持添加、更新、获取、删除、列表和统计操作 |
wechat_publish | write | 管理微信公众号文章发布 |
wechat_qrcode | read | 微信公众号二维码管理工具。创建临时/永久二维码,获取二维码图片URL。适用于渠道追踪、线下推广等场景。 |
wechat_short_url | read | 微信公众号长链接转短链接工具。将长URL转换为短链接,适用于二维码、短信等场景。 |
wechat_statistics | read | 微信公众号数据统计分析 - 获取图文、消息、接口等数据分析 |
wechat_subscribe_msg | read | 微信公众号订阅通知 - 发送一次性订阅通知给用户 |
wechat_tag | read | 微信公众号标签管理 - 创建、编辑、删除标签,为用户批量打标签/取消标签 |
wechat_template_msg | read | 微信公众号模板消息 - 发送模板消息、管理模板、设置行业、获取行业信息 |
wechat_upload_img | write | 上传图文消息内所需的图片,不占用素材库限制 |
wechat_user | read | 微信公众号用户管理 - 获取用户列表、用户信息、设置备注名、查看用户增减数据等 |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (2 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (7)
wechat-mcp.db
import { WechatMcpTool } from '../../mcp-tool/index.js';import { AuthManager } from '../../auth/auth-manager.js';import { logger } from '../../utils/logger.js';import { getVersion } from '../../utils/version.js';import { AuthManager } from '../../auth/auth-manager.js';@modelcontextprotocol/sdk, axios, commander, cors, crypto-js, dotenv, express, form-data
Gates applied: no_behavioural_pass.
ef650a6aba94full audit observations/trust-audit/mcp-server/xwang152-jack__wechat-official-account.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | ef650a6aba94 | SAFE | B | 89 | first audit |
Questions
What is the WeChat Official Account MCP server?
微信公众号MCP服务器 - WeChat Official Account MCP Server
What tools does WeChat Official Account expose?
21 in total: 17 read-only, 4 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is WeChat Official Account safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does WeChat Official Account need?
It reads WECHAT_MCP_SECRET_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does WeChat Official Account run?
It speaks sse and stdio, so it runs as a local process your client starts. It is published on npm as wechat-official-account-mcp at 2.2.0.
How current is this page?
The grade is for one exact copy of the source (ef650a6aba94), read on 2026-10-07. The repository is watched and re-audited when it changes.